Technology · Go
stdlib (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 161 vulnerabilities in stdlib (Go): 0 in the last 7 days and 4 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-56853, was published on 13 August 2026.
- Last 7 days
- 0
- Last 90 days
- 4
- Critical, all time
- 3
- Exploited in the wild
- 1
Latest stdlib (Go) vulnerabilities
- CVE-2026-56853: Go HTTP/2 timeout bypass in unencrypted connectionshighCVSS 7.5EPSS 0.6%
- CVE-2026-46600: Google Go x/net denial of service in dnsmessage parsinginfoEPSS 0.6%
- CVE-2026-42505: Go crypto/tls information disclosure in Encrypted Client HelloinfoCVSS 0EPSS 0.4%
- CVE-2026-39822: Go os package path traversal via symlink with trailing slash in os.RootinfoEPSS 0.2%
- CVE-2026-42507: Google Go log injection in net/textproto packageinfoEPSS 0.4%
- CVE-2026-27145: Google Go CPU denial of service in crypto/x509 VerifyHostnameinfoCVSS 0EPSS 0.6%
- CVE-2026-39821: Go x/net idna privilege escalation via Punycode decodingcriticalCVSS 9.6EPSS 0.7%
- CVE-2026-42499: Google Go net/mail denial of service in consumePhrasehighCVSS 7.5EPSS 0.8%
- CVE-2026-39836: Google Go Denial of Service in net Package on WindowshighCVSS 7.5EPSS 0.6%
- CVE-2026-39826: Google Go html/template XSS via script type attribute bypassmediumCVSS 6.1EPSS 0.4%
- CVE-2026-39825: Go ReverseProxy parameter smuggling via query limit mismatchmediumCVSS 5.3EPSS 0.4%
- CVE-2026-39823: Go html/template XSS via improper escaping in meta tagsmediumCVSS 6.1EPSS 0.3%
- CVE-2026-39820: Go net/mail denial of service in email and date parsinghighCVSS 7.5EPSS 0.9%
- CVE-2026-33814: Go net/http infinite loop in HTTP/2 SETTINGS frame processinghighCVSS 7.5EPSS 0.8%
- CVE-2026-33811: Go net package double-free in cgo DNS resolverhighCVSS 7.5EPSS 0.9%
- CVE-2026-33810: Google Go crypto/x509 improper DNS constraint validationhighCVSS 8.2EPSS 0.3%
- CVE-2026-32289: Go html/template XSS in JS template literalsmediumCVSS 6.1EPSS 0.3%
- CVE-2026-32288: Go archive/tar unbounded memory allocation in sparse map parsingmediumCVSS 5.5EPSS 0.2%
- CVE-2026-32283: Google Go crypto/tls denial of service via TLS 1.3 key update deadlockhighCVSS 7.5EPSS 0.7%
- CVE-2026-32282: Go standard library symlink traversal in Root.Chmod on LinuxmediumCVSS 6.4EPSS 0.2%
- CVE-2026-32281: Google Go crypto/x509 denial of service in certificate validationhighCVSS 7.5EPSS 0.4%
- CVE-2026-32280: Google Go denial of service in crypto/x509 certificate chain buildinghighCVSS 7.5EPSS 0.7%
- CVE-2026-27137: Google Go crypto/x509 improper certificate validation in email constraintshighCVSS 7.5EPSS 0.7%
- CVE-2026-25679: Google Go net/url insufficient validation of IPv6 host literalshighCVSS 7.5EPSS 0.8%
- CVE-2026-27138: GO-2026-4600 - Panic in name constraint checking for malformed certificates in crypto/x509infoEPSS 0.3%
Most severe stdlib (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-0601: GO-2022-0535 - Certificate validation bypass on Windows in crypto/x509criticalexploited in the wildCVSS 8.1EPSS 89.4%
- CVE-2026-39821: Go x/net idna privilege escalation via Punycode decodingcriticalCVSS 9.6EPSS 0.7%
- CVE-2025-22871: Go net/http request smuggling via bare LF in chunked encodingcriticalCVSS 9.1EPSS 0.8%
- CVE-2026-33810: Google Go crypto/x509 improper DNS constraint validationhighCVSS 8.2EPSS 0.3%
- CVE-2020-16845: Go encoding/binary infinite loop in ReadUvarint and ReadVarinthighCVSS 7.5EPSS 4.7%
- CVE-2025-61726: Go net/url memory exhaustion in query parameter parsinghighCVSS 7.5EPSS 2.3%
- CVE-2026-33811: Go net package double-free in cgo DNS resolverhighCVSS 7.5EPSS 0.9%
- CVE-2026-39820: Go net/mail denial of service in email and date parsinghighCVSS 7.5EPSS 0.9%
- CVE-2026-42499: Google Go net/mail denial of service in consumePhrasehighCVSS 7.5EPSS 0.8%
- CVE-2026-25679: Google Go net/url insufficient validation of IPv6 host literalshighCVSS 7.5EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/go-stdlib.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "stdlib (Go) vulnerabilities", https://junglewise.ai/threats/technologies/go-stdlib, 28 September 2026.